Forensic Analysis of 7-Zip Archive Metadata

Digital forensics investigators frequently examine 7-Zip (.7z) archives to uncover evidence of data exfiltration, malware staging, and file tampering. This article details how investigators locate, extract, and interpret metadata embedded within the 7-Zip container format, explaining the technical structure of 7z headers, the critical timestamps and attributes preserved during compression, and the methodologies used to analyze both cleartext and encrypted archives.

The Architecture of 7-Zip Metadata

Unlike standard ZIP files that store metadata in local file headers preceding each compressed file, the 7-Zip format consolidates metadata into dedicated header structures. A standard .7z file begins with a 32-byte Start Header that contains a specific signature (37 7A BC AF 27 1C), version information, and a relative offset pointing to the Main Header (often called the End Header).

The Main Header contains the complete metadata catalog for the archive, including:

  • File Hierarchy: Original filenames, directory paths, and folder structures.
  • Stream Descriptors: Uncompressed sizes, packed sizes, and compression method identifiers (e.g., LZMA, LZMA2, PPMd, BZip2).
  • Data Integrity Values: CRC-32 checksums for each individual stream.
  • File Attributes: Standard Windows/DOS attributes (such as Read-Only, Hidden, System, and Archive flags).

Extracting Forensic Timestamps

7-Zip preserves high-resolution timestamps, which are critical for building digital forensic timelines. By default, 7-Zip stores timestamps in the Windows FILETIME structure—a 64-bit value representing 100-nanosecond intervals since January 1, 1601 (UTC).

Investigators analyze up to three distinct timestamps per file:

  1. Last Modified Time (MTime): Included by default in most 7-Zip archives.
  2. Creation Time (CTime): Captured if the archive was created using specific switches or modern GUI versions configured to preserve complete time records.
  3. Last Access Time (ATime): Preserved conditionally depending on the host operating system's settings and creation flags.

Forensic practitioners compare these internal timestamps against the external file system timestamps of the .7z container itself. A discrepancy where internal files have creation or modification times newer than the container’s creation time suggests archive manipulation, container copying, or potential timestomping.

Methods and Tools for Metadata Extraction

Investigators rely on both native command-line utilities and specialized digital forensics platforms to parse metadata without modifying the original evidence.

Technical Command-Line Extraction

The 7-Zip command-line tool provides a raw, structured dump of all metadata using the -slt (Show Technical Information) switch:

7z l -slt target_archive.7z

This output displays the exact compression method, physical block sizes, characteristics, CRC values, and complete 64-bit timestamps for every entry.

Automated Forensic Suites

Tools such as Magnet AXIOM, OpenText EnCase, and Autopsy automatically parse 7-Zip containers during ingestion. These suites parse the central header, extract individual file entries into the case database, and populate the master timeline with internal metadata, allowing investigators to correlate compressed file activity with system logs and registry events.

Low-Level Hex and Python Parsing

When an archive is damaged, truncated, or subjected to anti-forensic wiping, examiners parse raw byte sequences using hex editors or libraries like py7zr. Investigators search for the kEnd marker (0x00) and metadata property IDs (such as kCTime [0x13], kMTime [0x14], and kWinAttributes [0x15]) to manually reconstruct archive contents when headers cannot be automatically read.

Investigating Encrypted Archives

7-Zip supports AES-256 encryption in two modes, each presenting different investigative scenarios:

  1. Standard Payload Encryption: The compressed data streams are encrypted, but the Main Header remains unencrypted. In this state, investigators can view all metadata—including file names, directory trees, file sizes, and timestamps—without requiring the decryption password. This allows examiners to prove that sensitive data was staged even if the file contents cannot be decrypted.
  2. Header Encryption (-mhe=on): Both the data streams and the Main Header are encrypted. The initial 32-byte Start Header remains visible, indicating the archive type and encryption parameters, but all file names, timestamps, and attributes are hidden. In this scenario, examiners must recover the passphrase through memory analysis (extracting keys from process memory), credential harvesting, or targeted password recovery attacks before any metadata can be parsed.